DEV Community

Discussion on: So you think you're just gonna `npm install`? Think again

saurabhdaware profile image
Saurabh Daware ๐ŸŒป

Hi, great article! I have a question:
So I've seen dependabot updating package-lock file in its commits, so how does it work? Does changing the integrity hash in package-lock.json change things ?

lirantal profile image
Liran Tal Author

if you run an npm install with npm ci then npm will only consult the lockfile, and so changing the lockfile directly will work.